Is That AI Tool Legit? How to Spot Malware in Disguise
Malware disguised as AI tools hit SMBs 33,300+ times in early 2026, a near 5x surge. Here's a concrete checklist to verify any AI service before you touch it.
Attackers are wrapping malware inside fake AI tools, and SMBs are the primary target. From January to April 2026, Kaspersky detected more than 33,300 attacks on SMBs where malicious software was disguised as popular AI services, a near 5x increase over the prior period. The attack surface is simple: someone on your team searches for a ChatGPT plugin, a free image generator, or an AI writing tool, lands on a convincing fake, and downloads a credential-stealing payload. The checklist below tells you exactly how to verify before anyone on your team clicks install.
Why are attackers disguising malware as AI tools right now?
Because demand for AI tools is high, familiarity with legitimate sources is low, and most SMBs have no procurement checklist for software. That combination makes for easy targeting.
Kaspersky research published in June 2026 found more than 33,300 attacks on small and medium-sized businesses in just four months, where the malware was specifically disguised as popular AI services. That number is nearly five times higher than the comparable period the year before. This is not a slow trend. It is a fast-moving targeting shift.
The mechanics are straightforward. An employee wants to try an AI tool. They search for it, find a convincing clone site or a pirated installer, and download it. The payload can be anything: a keylogger, a credential stealer, ransomware staging. The AI branding is just the lure.
What kinds of AI tools are being faked?
The fakes tend to cluster around the most-searched AI products because that is where the traffic is. Think ChatGPT desktop clients, Midjourney installers, AI writing assistants, and productivity tools that have heavy buzz but no official desktop download yet. If the real product does not have a native desktop app, a fake installer for it has almost no legitimate competition in search results.
This matters for your team because the people most likely to download something risky are often the most enthusiastic early adopters, not the least technical employees. Curiosity is the attack vector.
"The AI branding is just the lure. The payload is what they actually came for."
Which attack types show up most often?
Based on the Kaspersky findings and consistent patterns in SMB-targeted campaigns, the common payloads include:
- Trojan-PSW (password stealers): Harvest browser credentials, saved passwords, and session cookies
- Adware bundlers: Lower severity but a reliable sign of a compromised source
- Backdoor installers: Give attackers persistent access for later use
- Ransomware droppers: Stage an attack that may not trigger for days or weeks
Password stealers are particularly damaging for SMBs because a single stolen session cookie can bypass multi-factor authentication entirely on many SaaS platforms.
How do you verify an AI service before downloading or signing up?
This is the practical question. Here is a concrete checklist your team can actually use.
Step 1: Confirm the official domain
Search the product name plus "official site" and cross-reference with the company's verified social accounts. Look at the domain carefully. Attackers use typosquatting (chatgp-t.com, midjoureny.com) and subdomain tricks (app.chatgpt.fakesite.com). The real domain is always in the URL bar, not just the page content.
Step 2: Check where downloads actually come from
Legitimate AI tools distributed as desktop apps come from their own official domains, the Mac App Store, or the Microsoft Store. If you found a download link through a third-party site, Reddit post, or search ad, go back and find the official source directly. A 30-second detour is worth it.
Step 3: Verify the publisher signature on any installer
On Windows, right-click the downloaded file, go to Properties, then Digital Signatures. The signer should match the company name exactly. On Mac, check that Gatekeeper approves it and the developer identity matches. An unsigned installer or one signed by a generic LLC you do not recognize is a hard stop.
Step 4: Run the installer hash against VirusTotal
VirusTotal lets you upload a file or paste a hash and checks it against 70+ antivirus engines in seconds. This takes about one minute and catches most known malware variants. Make this a required step before installing any new software tool across your organization.
Step 5: Confirm the tool actually needs the permissions it requests
An AI writing assistant does not need access to your contacts, camera, or microphone. An image generator does not need your keychain. When an installer requests permissions that do not match its stated function, that is a signal worth acting on.
What should your internal policy actually say?
Most SMBs have no formal AI tool procurement policy yet. That gap is exactly what these attacks exploit. A workable policy does not need to be long. It needs to cover three things:
| Policy element | What it means in practice | |---|---| | Approved sources list | A short list of verified domains and stores where tools can be downloaded from | | One-person approval gate | Any new AI tool requires sign-off from one designated person before installation | | VirusTotal check required | No exceptions for installers, regardless of how trusted the source appears |
This is not bureaucracy. It is a 10-minute process that your team runs once per tool. The cost of one credential-theft incident, including recovery, downtime, and potential customer notification requirements, is orders of magnitude higher.
Does this apply to browser extensions and web apps too?
Yes, and this is an underappreciated surface. Browser extensions requesting broad permissions (read and change all your data on websites you visit) are a common delivery mechanism. Web apps that ask you to connect your Google account or Microsoft 365 via OAuth are requesting real access to real data.
For browser extensions: only install from the Chrome Web Store or Firefox Add-ons, check the developer identity, and look at the permission scope before accepting. An AI tool that needs to read every page you visit is worth a hard look.
For OAuth connections: review what scopes an app is requesting before you authorize. "Read your email" is very different from "Send email on your behalf."
What we'd actually do
- Build a one-page approved tools list this week. It does not need to be comprehensive. Start with the tools your team already uses and add a simple approval process for anything new. A shared Google Doc works fine.
- Make VirusTotal a muscle memory step. Add it to your onboarding checklist and any IT or operations documentation you have. One designated person should own this for your org.
- Audit browser extensions across your team. Ask everyone to open their extension manager and share a screenshot. You will likely find several tools no one remembers installing. Remove anything with broad permissions that you cannot verify.
FAQ
How do I know if an AI tool download is safe?
Download only from the official product domain, the Mac App Store, or the Microsoft Store. Before running any installer, upload the file to VirusTotal and check the digital signature matches the real company name. If you found the download through a search ad or third-party site, go find the official source directly instead.
How many SMBs were targeted by AI-disguised malware in 2026?
Kaspersky detected more than 33,300 attacks on SMBs from January to April 2026 where malware was disguised as popular AI services. That figure represents a near 5x increase over the equivalent period the prior year, according to research published in June 2026.
Do I need a formal policy to protect my team from fake AI tools?
You need a simple one, not a complex one. An approved sources list, a single sign-off requirement before any new tool is installed, and a mandatory VirusTotal check covers the vast majority of risk. That is a 10-minute process per tool, and it closes the gap that most of these attacks exploit.
Want this running in your business?
The Skool community is where we show the full builds, share the templates, and help you implement. Three tiers, from team training to fractional AI expert.
- Weekly Q&A with Alex and Cameron
- Templates and frameworks you can steal
- Real builds, running in real businesses
More on Governance
Your Claude Chats May Be Publicly Indexed on Google
Claude users' private chats showed up in Google search results, exposing medical records and student data. Here's what SMB owners need to audit right now.
Claude Shared Chats Appeared in Google. Now What?
Anthropic's Claude share links surfaced in Google search results, exposing conversations. Here's what SMB owners must do before sharing AI chats with client data.
AI Agents Can Spend Your Money. Set the Rules First.
AI agents now execute purchases, not just recommendations. Here's how SMB operators set spending limits and guardrails before an agent runs up an unauthorized bill.